inside /etc/pve/firewall/<vmid>.fw ---------------- [sysrules] group ... IN ... OUT ... [rules] ... ------------- Where all rules inside [sysrules] have higher priority than other rules. Only System Admin can see/change those rules. good or bad idea?